Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Langgenius

First CVE: Mar 20, 2025Active for: 1 yearTotal CVEs: 31
48.7
VTI Score
High

Langgenius maintains Dify, an open-source platform for building and deploying large language model applications, which has attracted vulnerability research attention despite a narrow product footprint. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through access-control weaknesses, cross-site scripting, server-side request forgery, and origin validation errors that are characteristic of web-facing AI application frameworks where trust boundaries between user input, model inference, and external integrations demand careful enforcement. Defenders deploying or extending Dify should prioritize input validation, access control design, and network isolation for inference endpoints; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
15.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Langgenius over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2025
16 months ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-63387HIGH
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authenti
Dec 18, 20257.557NOYES
CVE-2026-61461HIGH
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search par
Jul 10, 20268.839NONO
CVE-2026-41948CRITICAL
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by ex
May 18, 20269.439NONO
CVE-2026-41947CRITICAL
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardle
May 18, 20269.137NONO
CVE-2025-56157CRITICAL
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the
Dec 18, 20259.835NONO
CVE-2025-63388CRITICAL
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissi
Dec 18, 20259.132NONO
CVE-2025-63386CRITICAL
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that
Dec 18, 20259.132NONO
CVE-2026-41949HIGH
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uplo
May 18, 20267.531NONO
CVE-2025-11750MEDIUM
In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accoun
Oct 22, 20255.330NOYES
CVE-2026-41950MEDIUM
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same
May 5, 20266.529NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
48%
32%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.2%)
Network30 (96.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (90.3%)
High3 (9.7%)
Unknown0 (0.0%)
User Interaction
None23 (74.2%)
Unknown0 (0.0%)
Required8 (25.8%)
Privileges Required
Low15 (48.4%)
High2 (6.5%)
None14 (45.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Langgenius.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Langgenius — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Langgenius's Products

View all 4 CNAs →

Top CWEs